Suped

Summary

SendGrid, a popular email service provider (ESP), often requires users to set up two DKIM (DomainKeys Identified Mail) records for domain authentication, typically labeled as s1._domainkey and s2._domainkey. This approach, while seemingly redundant to some users, is primarily driven by advanced security practices, specifically key rotation. Key rotation is a critical security measure that helps mitigate the risks associated with compromised private keys, ensuring the ongoing integrity and authenticity of email transmissions.

What email marketers say

Email marketers often encounter the requirement for multiple DKIM keys when setting up their domain authentication with ESPs like SendGrid. Their perspectives typically revolve around the practical implications of this setup, balancing security benefits with ease of configuration and potential troubleshooting.

Marketer view

Marketer from Email Geeks observes that SendGrid requests two domain keys, s1._domainkey.domain and s2._domainkey.domain, and questions the underlying reason since one key seems sufficient and high-availability doesn't appear to be the sole motive. They are seeking clarification on this setup.

08 Apr 2020 - Email Geeks

Marketer view

Marketer from Wix Studio Forum shares a solution to SendGrid domain authentication issues, advising users to select the Advanced settings during the authentication process. This action reveals the option to choose a custom DKIM, which is crucial for configuring domain authentication correctly.

10 Jan 2024 - Wix Studio Forum

What the experts say

Email deliverability experts highlight that SendGrid's requirement for two DKIM keys is a sophisticated approach to enhancing email security and maintaining sender reputation. Their insights delve into the technical rationale behind key rotation and the broader implications for email authentication.

Expert view

Expert from Email Geeks explains that the presence of multiple DKIM keys, typically CNAMEs pointing to key servers, is for key rotation. They state that any ESP not using this (or NS delegation) indicates a fundamental misunderstanding of email security implications.

08 Apr 2020 - Email Geeks

Expert view

Expert from SpamResource asserts that frequent key rotation is a cornerstone of modern email authentication security. They emphasize that while it adds operational overhead, it is indispensable for protecting against long-term exploitation of potentially compromised private keys.

20 Feb 2024 - SpamResource

What the documentation says

Official documentation from email service providers and security organizations often outlines the technical requirements and best practices for DKIM implementation. These resources typically explain the purpose of multiple DKIM keys in the context of domain authentication, focusing on operational continuity and security resilience.

Technical article

SendGrid documentation states that when authenticating a domain on a SendGrid account, users must utilize the Custom DKIM Selector option to correctly configure their domain authentication. This ensures that the appropriate DKIM records are generated and linked to their sending domain.

20 Nov 2023 - SendGrid Support

Technical article

DuoCircle documentation explains that the presence of multiple DKIM records simplifies the process of updating keys without interruption. By employing a new selector for each updated key, organizations can transition to a new key seamlessly, thereby preventing downtime in their email service.

15 Mar 2024 - DuoCircle

9 resources

Start improving your email deliverability today

Get started